Short answer: Your VPN is leaking DNS if your DNS queries are being resolved by a server you did not deliberately choose — your ISP's resolver, or any third-party resolver that isn't operated by your VPN or your chosen privacy provider. To check, run an online DNS-leak test while connected: the result shows which DNS servers are answering your lookups. If those servers belong to your ISP or to a resolver you never configured, DNS is leaking — meaning your provider can still see which domains you look up even though your traffic is encrypted.
How do I know if my VPN is leaking DNS?
1. Connect your VPN, then run a DNS-leak test
Use a reputable online DNS-leak test. It shows which DNS servers are answering your lookups while connected.
2. Read the result
DNS is leaking if the resolver shown is anything you did not deliberately choose — your ISP, or any third-party resolver that isn't your VPN's. A leak isn't only your ISP.
- If the listed servers belong to your VPN provider's resolver (or a resolver your VPN explicitly routes through), DNS is going through the tunnel.
- If they belong to your ISP or to a server you never configured, DNS is leaking.
Note: IPv6 and OS-level fallback resolvers can leak even when the IPv4 test passes — test with IPv6 enabled to catch these.
3. Re-test on cellular and public Wi-Fi
Leaks can be intermittent — they may show up only on some networks or after your device reconnects from sleep, so test in more than one place.
4. Why DNS leaks matter
Even with encrypted traffic, leaked DNS queries reveal the domains you visit — enough to profile your browsing.
5. How to fix it
Use protection that handles DNS resolution and filtering itself rather than handing lookups back to your ISP, and that keeps the tunnel hardened so requests don't fall outside it. Beyond simply routing DNS through a tunnel, look for a layer that actively filters DNS — blocking malicious domains, trackers, and phishing infrastructure at the resolver level, which a plain encrypted tunnel alone does not do.
Where Casper's Cloak fits
Casper's Cloak pairs DNS/network-level filtering with an encrypted WireGuard tunnel and kill-switch-style tunnel hardening. DNS lookups are filtered and protected — blocking malicious domains, trackers, and phishing infrastructure — rather than handed back to your provider. That filtering layer is what separates it from a plain tunneled connection: the same clean leak-test result comes with active threat filtering on top, across iPhone, Android, and Mac.